Personal Information Protection Act
Illinois · Business Transactions · §§ 815-530-1 to 815-530-900 · 12 sections
Overview
This act governs how businesses and government agencies handle personal information about individuals, covering data-security breaches, security freezes on credit information, the use of Social Security numbers, and the disposal of records containing personal data. It requires notice to affected individuals — and in certain cases to other agencies — after a breach of security, lets a person place, confirm, and remove a freeze restricting access to their credit information, and limits when Social Security numbers may be requested, collected, disclosed, sold, or otherwise transferred, subject to exceptions for employees, agents, and specified employment purposes. Entities holding personal records must adopt protective policies and procedures and exercise due diligence in destroying those records, with noncompliance enforceable through civil penalties and court action.
Editorial summary generated from the text of this act. It is not part of the statute — read the sections below for the operative language.
Sections covered
- 815 ILCS 530/1Short title
- 815 ILCS 530/10Notice of breach; notice to Attorney General
- 815 ILCS 530/12Notice of breach; State agency
- 815 ILCS 530/15Waiver
- 815 ILCS 530/20Violation
- 815 ILCS 530/25Annual reporting
- 815 ILCS 530/30Safe disposal of information
- 815 ILCS 530/40Disposal of materials containing personal information; Attorney General
- 815 ILCS 530/45Data security
- 815 ILCS 530/5Definitions
- 815 ILCS 530/50Entities subject to the federal Health Insurance Portability and Accountability Act of 1996
- 815 ILCS 530/900(Amendatory provisions; text omitted)
Enacted in other states
Download
Copy
Embed on your site
Hover to preview · click to copy the code